# CVE-2026-48800

> As of 2026-09-13, CVE-2026-48800 is a HIGH-severity vulnerability, CVSS v3.1 7.8, EPSS 0.0% (5.7th percentile). Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2026-48800, most recently “Notepad++ v8.9.6 — Critical Arbitrary Code Execution via config.xml commandLineInterpreter and shortcuts.xml (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)”.

**Last updated:** 2026-09-13

## What is CVE-2026-48800?

Notepad++ allows arbitrary code execution via the tag inside UserDefinedCommands in the shortcuts.xml configuration file. The tag text in within shortcuts.xml is read without validation and stored in UserCommand._cmd; when executed via the Run menu it invokes ShellExecute with the attacker-controlled string as the executable path, enabling arbitrary code execution in the context of the current user. It affects all Notepad++ versions up to and including v8.9.6 and is fixed in v8.9.6.1.

The record classifies CVE-2026-48800 under weakness class [CWE-78](https://cwe.mitre.org/data/definitions/78.html). Its CVSS v3 base vector states that the flaw requires local access to the host, needs no prior authentication, needs a user to take an action first, and has high impact on confidentiality, integrity, availability.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 7.8 — HIGH (`CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H`)
- **EPSS (FIRST):** 0.0% probability of exploitation in the next 30 days, higher than 5.7% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 4.1/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability

## Is CVE-2026-48800 being exploited?

It currently carries a trending score of 6 in the Threadlinqs vulnerability feed.

## Affected products and versions

No affected-product or package list has been recorded for CVE-2026-48800 in the tracked sources. The vendor advisory and the references below are the authoritative statement of what is affected.

## How to fix CVE-2026-48800

No vendor patch reference has been recorded for CVE-2026-48800 in the tracked sources. Follow the references below for a fix, and treat any affected deployment as exposed until the vendor states otherwise.

## Threat activity tracking CVE-2026-48800

1 tracked threat in the Threadlinqs corpus references CVE-2026-48800, either in the campaign’s CVE list or as an indicator on the campaign record.

- [Notepad++ v8.9.6 — Critical Arbitrary Code Execution via config.xml commandLineInterpreter and shortcuts.xml (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)](https://intel.threadlinqs.com/threat/TL-2026-0613) — CRITICAL · 2026-05-28

## Sources

Seeded from `research_verified` and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.

- [github.com](https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-3x3f-3j39-pj3v)

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-48800
Full detection coverage and IOCs for threats exploiting CVE-2026-48800 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
